Attackers offer a service or favor in exchange for sensitive information.
A typical quid pro quo attack: an attacker calls employees at a company posing as IT support, offering to fix a performance problem or speed up their computer. Most employees decline, but eventually one agrees. The "technician" asks for their credentials to "run diagnostics remotely."
The victim gets "help" — the attacker performs some superficial action that appears to fix something — and the attacker gets valid credentials. The exchange feels fair. That perceived fairness is exactly what makes the attack work.
Quid pro quo attacks succeed because they feel like a reasonable transaction, not an attack. "They helped me — it's only fair that I help them." Recognizing this feeling as a potential manipulation cue — rather than a social obligation — is the core defense.
Legitimate IT departments never ask for your password over the phone or email. They have administrative tools that do not require your credentials. Any request for your password from IT support — regardless of how helpful or official they seem — should be refused and reported.